Public notice
Security Reporting
Report a suspected PUPMKT security issue privately to Dravara, LLC.
Published for review. Not yet in effect.
Applicability
Published by Dravara, LLC. This notice describes the scope and practices stated below. Publication does not activate an unavailable service or, by itself, establish a user's agreement to a contractual provision.
A contractual provision requiring your agreement applies only where there is a legally effective agreement and only to the extent permitted by applicable law. Nothing published here makes privacy rights, other nonwaivable rights or Dravara's legal obligations depend on your accepting a contractual provision.
Third-party names and marks remain their owners' property, and their appearance does not imply affiliation, sponsorship, endorsement or participation. A partnership, acquisition, licensing or other commercial relationship requires a separate written agreement.
Reporting and rules of engagement
- Report a suspected PUPMKT security issue privately to security@pupmkt.com. Include the affected page or component, reproducible steps, the apparent impact and non-sensitive evidence. Do not send credentials, full payment-card details or other people's private data in an initial report. Ask for a suitable secure exchange method if sensitive evidence is necessary.
- Do not conduct destructive testing, disrupt service, persist in a system, use social engineering, or access data beyond what is reasonably necessary to identify an issue. If you encounter another person's information, stop, do not copy or disclose it, and report what happened safely. This page does not authorize testing a third-party service, promise a bounty, grant immunity from applicable law or promise round-the-clock response. Dravara reviews reports and coordinates follow-up as appropriate.
